Cybercrime Law in Germany

Germany addresses computer crime through dedicated sections of its Criminal Code (Strafgesetzbuch, StGB), alongside EU-derived data-protection law.

Key laws

  • StGB § 202a — Ausspähen von Daten (data espionage): obtaining access, for oneself or another, to data that is not intended for the offender and is specially protected against unauthorised access, by circumventing that protection. Up to three years’ imprisonment or a fine.
  • StGB § 202b — Abfangen von Daten (interception of data): unlawfully obtaining data not intended for the offender by technical means from a non-public data transmission or from the electromagnetic emissions of a data-processing installation. Up to two years or a fine.
  • StGB § 202c — Vorbereiten des Ausspähens und Abfangens von Daten — preparatory acts, the much-debated “hacker tools” provision: producing, obtaining, selling or distributing passwords, access codes or software designed to commit an offence under §§ 202a or 202b.
  • StGB § 202d — Datenhehlerei — handling data that another person obtained unlawfully, with exemptions for certain official and professional activities.
  • StGB § 303a — Datenveränderung (unlawfully deleting, suppressing, rendering unusable or altering data) and StGB § 303b — Computersabotage (substantially interfering with data processing of importance to another), with an aggravated range of six months to ten years in particularly serious cases, including attacks on critical infrastructure.
  • Bundesdatenschutzgesetz (BDSG) together with the EU GDPR — data protection, security of processing and breach obligations.

Germany is a party to the Budapest Convention on Cybercrime (ETS 185), which it ratified on 9 March 2009 and which entered into force for Germany on 1 July 2009.

Enforcement

The Bundeskriminalamt (BKA) and the state (Länder) police forces investigate cybercrime, with central cybercrime units in several state prosecution services. The BSI (Bundesamt für Sicherheit in der Informationstechnik) is the federal information-security authority, and the federal and state data-protection authorities enforce the GDPR and the BDSG.


Plain-language overview, not legal advice. Statutes change — read the current text linked above and seek qualified advice for any specific matter.

Sources verified 9 August 2026 against gesetze-im-internet.de (Bundesministerium der Justiz) and EUR-Lex.